Re: [webkit-gtk] How to fix CVEs of webkitgtk 2.36.x

2023-03-27 Thread 不会弹吉他的KK
On Wed, Mar 22, 2023 at 7:01 PM Michael Catanzaro wrote: > On Wed, Mar 22 2023 at 11:26:56 AM +0200, Adrian Perez de Castro > wrote: > > Recently advisories published by Apple include the Bugzilla issue > > numbers > > (e.g. [1]), so with some work you can find out which commits > > correspond

Re: [webkit-gtk] How to fix CVEs of webkitgtk 2.36.x

2023-03-22 Thread Michael Catanzaro
On Wed, Mar 22 2023 at 11:26:56 AM +0200, Adrian Perez de Castro wrote: Recently advisories published by Apple include the Bugzilla issue numbers (e.g. [1]), so with some work you can find out which commits correspond to the fixes. It finally occurs to me that since Apple now publishes the

Re: [webkit-gtk] How to fix CVEs of webkitgtk 2.36.x

2023-03-22 Thread Adrian Perez de Castro
Hello, On Wed, 22 Mar 2023 11:57:24 +0800 不会弹吉他的KK wrote: > I am working on Yocto project. In last LTS Yocto release the version of > webkitgtk is 2.36.8. And there are more than 15 CVE issues for 2.36.8 till > now. I checked the git log and "WebKitGTK and WPE WebKit Security Advisory" > pages

[webkit-gtk] How to fix CVEs of webkitgtk 2.36.x

2023-03-21 Thread 不会弹吉他的KK
Hi All, I am working on Yocto project. In last LTS Yocto release the version of webkitgtk is 2.36.8. And there are more than 15 CVE issues for 2.36.8 till now. I checked the git log and "WebKitGTK and WPE WebKit Security Advisory" pages that I only got info that which CVE has been fixed in which